PT-2023-12244 · Htmodoc+3 · Htmodoc+3

Chibataiki

·

Published

2023-07-18

·

Updated

2025-01-08

·

CVE-2021-34121

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions htmodoc version 1.9.12
Description An Out of Bounds flaw was discovered in the parse tree() function in toc.cxx, which possibly leads to memory layout information leaking in the data. This might be used in a chain of issues to reach code execution.
Recommendations For version 1.9.12, consider restricting access to the parse tree() function in toc.cxx until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2021-34121
USN-7189-1

Affected Products

Debian
Linuxmint
Ubuntu
Htmodoc